DRIVE-022: Content distribution to outside shared drives blocked (GWS.DRIVEDOCS.1.7)
- Platform
- Google Workspace
- Category
- Drive Security & Data Protection
- Severity
- Medium
- Zero Trust pillar
- Data (weight 2)
- Golden fixtures
- 5
- Branch coverage
- Declared verdict paths, each proven by a fixture
- Provenance
- baseline
What it checks
SCuBA GWS.DRIVEDOCS.1.7: moving a file into a shared drive owned by another organization transfers custody of it — the receiving organization's admins control the content and the organization that created it loses the ability to revoke access or retain it. Reads drive_and_docs.external_sharing and fails where allowedPartiesForDistributingContent is anything other than NONE in a policy whose externalSharingMode permits external sharing. Not applicable where external sharing is disallowed.
Recommended value
No party may upload or move content into shared drives owned by another organization
Remediation
Admin console > Apps > Google Workspace > Drive and Docs > Sharing settings > 'Distributing content outside of <organization>'. Set it so that no one is allowed to distribute content to shared drives owned by another organization.
Fixture-proven verdicts
Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.
| Scenario | Expected verdict |
|---|---|
| clean | PASS |
| field-missing | Not Assessed |
| known-bad | WARN |
| not-applicable | PASS |
| not-assessed | Not Assessed |
Framework mappings
- CISA SCuBA
- GWS.DRIVEDOCS.1.7v1
- NIST SP 800-53
- AC-3, AC-4, SC-7
- MITRE ATT&CK
- T1537